US2020322168A1PendingUtilityA1

Privacy preserving ip traceback using group signature

Assignee: AGENCY SCIENCE TECH & RESPriority: Nov 30, 2017Filed: Nov 30, 2017Published: Oct 8, 2020
Est. expiryNov 30, 2037(~11.3 yrs left)· nominal 20-yr term from priority
H04L 9/3255H04L 9/0833H04L 9/3297H04L 69/22
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, a computer-readable medium, and an apparatus for IP traceback are provided. The apparatus may generate a group public key shared by a plurality of routers controlled by a service provider. The apparatus may generate a unique private signing key for a router of the plurality of routers. The private signing key may be used to generate a group signature for a session of network traffic. The group public key may be applied to the group signature to identify the service provider. The apparatus may identify the router by applying the group public key and a master secret key to the group signature. The apparatus may deploy preventive or mitigate action on the identified router.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of IP traceback, comprising:
 generating a group public key shared by a plurality of routers controlled by a service provider;   generating a unique private signing key for a router of the plurality of routers, wherein the private signing key is used to generate a group signature for a session of network traffic, wherein the group public key is applied to the group signature to identify the service provider; and   identifying the router by applying the group public key and a master secret key to the group signature.   
     
     
         2 . The method of  claim 1 , wherein the session of network traffic comprises a set of packets with a same set of header information and the set of packets are correlated in time, wherein the set of header information comprises a destination IP address, a destination port, and a protocol. 
     
     
         3 . The method of  claim 1 , further comprising sending the group public key to a trusted authority, wherein the master secret key is prohibited from being sent to the trusted authority. 
     
     
         4 . The method of  claim 1 , further comprising generating the master secret key. 
     
     
         5 . The method of  claim 1 , wherein the group signature is generated based on session specific information of the session of network traffic. 
     
     
         6 . The method of  claim 5 , wherein the session specific information comprises a session identifier and a timestamp. 
     
     
         7 . The method of  claim 1 , wherein the group signature is appended to a signature packet, wherein the signature packet comprises a plurality of group signatures generated by a subset of the plurality of routers. 
     
     
         8 . The method of  claim 1 , further comprising deploying preventive or mitigate action on the router. 
     
     
         9 . The method of  claim 1 , wherein the group signature is partially generated before the session of network traffic arrives at the router. 
     
     
         10 . An apparatus for IP traceback, comprising:
 a memory; and   at least one processor coupled to the memory and configured to:
 generate a group public key shared by a plurality of routers controlled by a service provider; 
 generate a unique private signing key for a router of the plurality of routers, wherein the private signing key is used to generate a group signature for a session of network traffic, wherein the group public key is applied to the group signature to identify the service provider; and 
 identify the router by applying the group public key and a master secret key to the group signature. 
   
     
     
         11 . The apparatus of  claim 10 , wherein the session of network traffic comprises a set of packets with a same set of header information and the set of packets are correlated in time, wherein the set of header information comprises a destination IP address, a destination port, and a protocol. 
     
     
         12 . The apparatus of  claim 10 , wherein the at least one processor is further configured to send the group public key to a trusted authority, wherein the master secret key is prohibited from being sent to the trusted authority. 
     
     
         13 . The apparatus of  claim 10 , wherein the at least one processor is further configured to generate the master secret key. 
     
     
         14 . The apparatus of  claim 10 , wherein the group signature is generated based on session specific information of the session of network traffic. 
     
     
         15 . The apparatus of  claim 14 , wherein the session specific information comprises a session identifier and a timestamp. 
     
     
         16 . The apparatus of  claim 10 , wherein the group signature is appended to a signature packet, wherein the signature packet comprises a plurality of group signatures generated by a subset of the plurality of routers. 
     
     
         17 . The apparatus of  claim 10 , wherein the at least one processor is further configured to deploy preventive or mitigate action on the router. 
     
     
         18 . The apparatus of  claim 10 , wherein the group signature is partially generated before the session of network traffic arrives at the router. 
     
     
         19 . A computer-readable medium storing computer executable code, comprising instructions for:
 generating a group public key shared by a plurality of routers controlled by a service provider;   generating a unique private signing key for a router of the plurality of routers, wherein the private signing key is used to generate a group signature for a session of network traffic, wherein the group public key is applied to the group signature to identify the service provider; and   identifying the router by applying the group public key and a master secret key to the group signature.   
     
     
         20 . The computer-readable medium of  claim 19 , further comprising instructions for deploying preventive or mitigate action on the router.

Join the waitlist — get patent alerts

Track US2020322168A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.